User and entity behavior analytics (UEBA) is a type of security analytics that compares the activity of users and entities, such as devices, servers, applications and service accounts, with what is normal for them or for similar peers, and flags behaviour that departs from it. Depending on the product and the data available, it uses individual baselines, peer-group baselines, rules, statistics or machine learning models. A user signing in at an unusual hour from a new country, a service account suddenly reading thousands of files, or a laptop connecting to systems it has never used are the kinds of anomalies it surfaces. It is designed to catch threats that don’t match a known signature, such as stolen credentials or a malicious insider.
At a glance
- UEBA compares activity with individual or peer-group norms, depending on the product and data, and scores deviations as risk.
- It targets threats that rule-based detection often misses: compromised accounts, insiders and attackers using legitimate tools.
- It relies on log data such as sign-ins, file access, network activity and endpoint events.
- It is often a feature of SIEM, XDR or identity security platforms rather than a standalone product.
- Unusual activity is not always malicious, so results need tuning and analyst judgement.
What problem it solves
Traditional detection looks for known bad things: malware signatures, blocked addresses, specific attack patterns. That struggles when the attacker logs in with a real username and password, or when the threat is an employee who already has legitimate access. Their actions use normal tools and permissions, so nothing matches a rule.
UEBA addresses that by asking a different question: is this normal for this user or system, or for its peers? An account that suddenly downloads far more data than usual, a finance user who starts accessing engineering servers, or an admin account active at 3 a.m. may each be innocent, but together they can reveal an insider threat or an attacker carrying out lateral movement. Combining signals into a risk score also helps analysts focus on the users most likely to matter.
How it works
Data collection. UEBA draws on logs from identity systems, endpoints, network devices, file servers, cloud and SaaS platforms, usually through a security information and event management (SIEM) platform or a central log management system.
Baselining. Using rules, statistics or machine learning models, depending on the product, it builds a picture of normal activity, for individual users and entities where there is enough data, and often for peer groups such as people in the same team or role.
Anomaly detection. New activity is compared with the relevant baselines, individual or peer group. Deviations, such as unusual times, locations, volumes or resources, are flagged.
Risk scoring. Individual anomalies are weighted and combined into a risk score per user or entity, so a cluster of small oddities can add up to an alert while a single one may not.
Investigation and response. Analysts review high-risk users with a timeline of the unusual activity. Integrations may trigger actions such as requiring re-authentication or disabling an account, depending on the platform and how it is configured.
When it matters for buyers
- When attackers use valid credentials. Phishing and credential theft make account misuse a common route in.
- When insider risk is a concern. Departing employees, contractors and privileged users handling sensitive data.
- When evaluating SIEM, XDR or identity security platforms. Check whether behaviour analytics are included, licensed separately or limited to certain data sources. Our SIEM overview explains how these platforms bundle analytics.
- When analysts are overwhelmed. Risk scoring can help prioritize, if tuned well; poorly tuned, it adds to false positive security alerts.
- When strengthening identity security. UEBA overlaps with identity threat detection and response (ITDR), which focuses specifically on identity systems.
Questions to ask vendors
- Which data sources does your UEBA use, and which do we need to provide?
- How long does it take to build reliable baselines, and how does it handle role changes and new staff?
- How are risk scores calculated, and can analysts see why a user was flagged?
- What is the typical alert volume for an organization of our size, and how is tuning handled?
- Is UEBA included in the platform price or licensed separately, and how is it measured?
- What automated responses can it trigger, and can we control them?
- How do you handle privacy, including limiting who can view individual activity?
How it differs from a SIEM
A SIEM collects and correlates logs and raises alerts mainly through rules written for known attack patterns. UEBA adds behavioural baselines (individual or peer-group) and anomaly scoring, which catch activity that looks normal to a rule but unusual for that particular user or system. Many SIEM platforms now include UEBA features, so the question for a buyer is less “SIEM or UEBA?” and more how good the behaviour analytics in the chosen platform are, and which data they cover.
